All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-67558
HIGHpublished 2026-08-11 22:18 UTC · 1 day ago · modified 2026-08-12 16:17 UTC
8.2
CVSS / 10
// description
The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement name only, with no cryptographic peripheral authentication, MAC allowlist, or bonded-identity check. An attacker could capture live session token information and inject forged hormone measurements into the victim's cloud record and clinical trend view.
// weaknesses (CWE)
- CWE-290